Skip to content

Privacy policy

What this site collects, exactly what the free tools transmit to third parties, how long anything is kept, and how to exercise your rights.

The short version: there are no user accounts, no advertising trackers and no data sales. The free tools do transmit some technical data to named third parties, and that is set out in full below rather than buried.

Last updated: 19 August 2026

#1. Who is responsible

proxy.wiki is an independent publication. We do not publish a corporate identity or a postal address. For any privacy matter, including access and erasure requests, write to [email protected] and we will respond.

#2. What we collect when you simply read a page

Data Why Who processes it
IP address, user agent, requested URL, referrer, timestamp Serving the page; diagnosing faults; detecting abuse Our web server, on infrastructure we control
The same, at the network edge Content delivery, TLS termination, bot filtering and denial-of-service protection Cloudflare, Inc., acting as our processor

We do not run advertising networks, cross-site trackers, session recorders, heatmaps or fingerprinting scripts. We do not build profiles of readers, and we do not sell, rent or trade personal data with anyone.

#3. What the free tools transmit

This is the section most privacy policies leave vague. Ours does not.

#Connection and leak test

When you open the tools page, your IP address is sent to ip-api.com to resolve country, city, ISP and network operator. We cache that result on our server for 24 hours, keyed against a hash of the address, so repeat visits do not repeat the lookup. Your request headers are read in memory to classify anonymity and are not stored.

#Proxy checker

The proxy details you enter — host, port and, if supplied, username and password — are used to open a single outbound request and are then discarded. They are never written to a database, a log file, or a cache. The exit address that request presents is sent to ip-api.com for the same geolocation lookup.

We nonetheless recommend you use a test account or rotate the credential afterwards. Any credential transmitted over a network is a credential you have exposed to that network path.

#WebRTC leak check

This runs entirely inside your browser. It contacts a public STUN server to enumerate candidate addresses. The result is displayed to you and is never transmitted to us.

#Cost calculator

Runs entirely in your browser against data already loaded with the page. Nothing you type is transmitted anywhere.

#4. Rate limiting

To keep the tools usable we store a counter against a hash of your IP address for up to ten minutes. The counter records how many requests have been made, not what they contained.

#5. Cookies and local storage

See the cookie policy for the complete list. In summary: no advertising cookies; your light or dark theme preference is stored in your browser’s local storage and never leaves your device; Cloudflare sets a security cookie necessary to deliver the site safely.

#6. Comments and avatars

Comments are closed by default across the site. Where they are enabled on a specific page, WordPress stores the name, email address and comment you submit, and may request an avatar image from Gravatar using a hash of your email address. You can ask us to delete a comment and its associated data at any time.

#7. Email you send us

If you write to us, we keep the message and your address for as long as needed to deal with the matter and to maintain a record of corrections we have made. We do not add correspondents to any mailing list.

Where the UK GDPR or EU GDPR applies to you, we rely on:

  • Legitimate interests — serving and securing the site, preventing abuse, and operating the diagnostic tools you have chosen to use.
  • Consent — where you actively submit something, such as a comment or an email.
  • Legal obligation — where we must retain or disclose something by law.

#9. International transfers

Cloudflare and ip-api.com operate infrastructure outside the country you are reading from. Where personal data is transferred internationally, it is protected by the transfer mechanisms those providers maintain, such as standard contractual clauses.

#10. How long we keep things

Data Retention
Web server logs Short-lived; kept only as long as needed for security and troubleshooting
Geolocation lookups 24 hours, cached against a hash
Rate-limit counters 10 minutes
Proxy credentials entered into the checker Never stored
Comments Until you ask us to remove them
Email correspondence As long as needed for the matter and our corrections record

#11. Your rights

Depending on where you live, you may have the right to access the personal data we hold about you, to have it corrected or erased, to restrict or object to its processing, to receive it in a portable format, and to withdraw consent.

Because we operate no accounts and store almost nothing, in most cases we hold nothing about you beyond short-lived server logs. Write to [email protected] and we will tell you honestly what we have, and act on your request.

If you are in the EEA or the UK and you are unhappy with our response, you may complain to your national data-protection authority.

#12. Children

This site is aimed at a technical and professional audience. It is not directed at children, and we do not knowingly collect data from them.

#13. Security

The site is served over TLS. Administrative access is restricted and protected by rate limiting. We do not store payment details, because we never take payments.

#14. Changes

Material changes to this policy will be reflected in the date at the top of this page and summarised here rather than made silently.